Following an incident in February affecting one of its bridge components, CrossCurve took an active step to strengthen its broader cross-chain architecture, performing a smart contract audit with Web3 security firm Hashlock on its LayerZero-based OFT messaging contracts. The audit, finalized in March 2026, resulted in a “secure” rating, with all identified vulnerabilities addressed within scope.
This commitment reflects a broader effort by the CrossCurve team to strengthen the security of its MetaLayer infrastructure beyond the contracts directly involved in the previous incident, thereby building confidence in the protocol’s cross-chain messaging stack.
What is CrossCurve?
CrossCurve is a cross-chain execution layer for DeFi, bringing together liquidity from major protocols – including 90+ DEXs, 40+ bridges, and intent-based solutions – into a unified routing system, enabling seamless exchanges from any token to any token across chains with optimized pricing and minimal slippage.
The protocol combines:
- cross-chain aggregators
- token bridge and messaging infrastructure
- Aggregated liquidity from local decentralized exchanges (DEX)
It provides Web3 projects with integration-ready infrastructure for seamless cross-chain operations, supporting gasless and private transactions, ZAP operations, and AI agent compatibility.
This eliminates cross-chain complexity, reducing the user experience to a single click.
Audit scope
Hashlock performed a manual line-by-line review of CrossCurve’s OFT messaging contracts on Ethereum, supported by software-assisted testing. The scope included five contracts that together govern how CrossCurve routes cross-chain token transfers through the LayerZero OFT framework:
CrossCurveCore.sol, the core contract extending LayerZero’s OFTCore and routing CrossCurve-enabled destinations through the protocol’s GateKeeper. OFTAdapter.sol and MintBurnOFTAdapter.sol, the two adapter variants responsible for locking and unlocking, or burning and minting, tokens during cross-chain transfers. CrossCurveOFTStorage.sol, a transient storage library handling the current context of the CrossCurve message. And OptionsReader.sol, a library handling LayerZero executor options for fee calculation.
Each contract has been examined against its intended functionality, with Hashlock confirming that all five behave as specified.
Conclusions and resolution
Hashlock’s review identified one medium severity issue, three low severity issues, and one quality assurance finding. All have been resolved.
The average finding focused on the routing logic in CrossCurveCore, where the native value sent by a caller could be locked under specific conditions if a destination was switched to the CrossCurve path between quoting and execution. The fix was simple but significant, the kind of edge-case problem that only becomes apparent through careful manual examination of cross-chain routing logic. The remaining findings were missing event broadcasts on the CrossCurve path, missing selector validation in the cross-chain authentication flow, an uninitialized return structure, and an unused storage constant.
After remediation, Hashlock gave the contracts a “Secure” rating, with the report indicating that the codebase follows industry best practices, makes appropriate use of OpenZeppelin libraries, and is well documented.
From incident to reinforced infrastructure
Cross-chain protocols have always been one of the most targeted layers in DeFi, with bridging exploits accounting for some of the largest losses in the industry’s history. The February incident affecting CrossCurve’s Axelar receiver contract, which resulted in losses of approximately $1.4 million, highlighted how implementation flaws in cross-chain validation logic can have outsized consequences.
The decision to audit a separate cross-chain messaging path reflects a more mature security posture, treating the bridge architecture as a continuous attack surface rather than a one-time deployment. By leveraging Hashlock to examine the LayerZero OFT layer, CrossCurve builds trust in the components that route user transfers across more than 20 supported chains.
Why bridge safety is important
Cross-chain infrastructure remains a structurally high-risk surface in DeFi. Messaging logic, receiver contract access control, and quorum configurations are all areas where small omissions can lead to large-scale exploits. As liquidity continues to flow across a growing set of chains, the protocols that gain user trust in the long term will be those that treat security as iterative, with regular reviews of evolving components rather than a single checkpoint before launch.
For projects creating or integrating cross-chain infrastructure, the CrossCurve engagement offers a model: respond to incidents by expanding the scope of independent review, not narrowing it.
Looking to the future
Once the OFT messaging contracts are reviewed and the findings resolved, CrossCurve is able to continue deploying its MetaLayer architecture to additional chains while maintaining a strong security foundation. The team reported continued investment in security across its broader stack, including ongoing external review of cross-chain components.
Resources
Hashlock audit page: hashlock.com/audits/crosscurve
CrossCurve website: crosscurve.fi
CrossCurve documentation: docs.crosscurve.fi
About Hashlock
Hashlock is a Web3 security company specializing in smart contract auditing and blockchain cybersecurity. Hashlock has conducted over 200 audits and helped secure over $1.3 billion in on-chain value across DeFi, infrastructure, gaming, and enterprise blockchain systems.
Website:
About CrossCurve
CrossCurve is a cross-chain execution layer for DeFi, bringing together liquidity from major protocols – including 90+ DEXs, 40+ bridges, and intent-based solutions – into a unified routing system.
It enables seamless exchanges from any token to any token across supported networks, while providing Web3 projects with integration-ready infrastructure for cross-chain operations, including gasless and private transactions, ZAP operations, and AI agent compatibility.
Website: crosscurve.fi
![]()



